How do I write a cybersecurity CV with no experience?
A practical breakdown of how career-changers can structure a cybersecurity resume around projects, labs, and transferable skills instead of job titles.
Hiring managers in security don't expect junior applicants to have a job history in the field. What they're checking for is whether you actually did the work of learning, not just claimed interest in it. The CV is where you prove that.
Lead with a skills-and-projects block, not a summary paragraph
Skip the generic "motivated professional seeking opportunities" line. It says nothing and wastes prime real estate at the top of the page. Instead, put a short block right under your name and contact info listing concrete tools and areas: "Nmap, Wireshark, Burp Suite, Splunk, Python scripting, Windows/Linux administration, TryHackMe Top 1%, OSCP in progress." A recruiter scanning fifty resumes decides in about six seconds whether to keep reading — give them keywords immediately.
Turn labs and CTFs into resume lines, not hobbies
Don't bury your practical work in a "hobbies" section at the bottom. If you completed TryHackMe's SOC Level 1 path, built a home lab with pfSense and a SIEM, or placed in a CTF, write it like a project:
- "Built a home SOC lab using Security Onion and Sysmon to detect and analyze simulated attacks (Atomic Red Team), writing detection notes for each technique tested."
- "Completed 40+ TryHackMe rooms covering Active Directory attacks, web exploitation, and log analysis; documented methodology and findings for each."
This does two things: it shows initiative, and it gives interviewers something specific to ask about, which plays to your advantage because you know these projects cold.
Map your old job to security language, honestly
If you're coming from IT support, network admin, or even an unrelated field, translate what you actually did into terms a security team recognizes. A helpdesk technician who handled phishing reports, reset compromised accounts, and enforced MFA rollout has real blue-team-adjacent experience — say that directly: "Triaged user-reported phishing emails, coordinated with IT security to reset 15+ compromised accounts, and supported organization-wide MFA rollout." Don't inflate a job title or claim you did incident response if you didn't. Recruiters and interviewers will find the gap fast, and it costs you credibility for the rest of the conversation.
Certifications belong near the top, but don't lead with acronyms alone
Security+, Network+, or an OSCP-in-progress note matters and should be visible without scrolling. But an acronym list next to zero context reads thin. Pair certs with what you did to get them or what came after: "CompTIA Security+ (2024) — followed with hands-on practice in TryHackMe's Jr Penetration Tester path to reinforce exam concepts with real tooling." That sentence tells a hiring manager you don't just collect certs, you apply what's in them.
One page, unless you genuinely have more to say
For anyone with under five years of professional experience, one page is standard. Cramming a two-page resume with padded bullet points to look experienced backfires — it dilutes the strong lines with weak ones. Cut anything that doesn't map to the job description in front of you. Tailor per application: if the posting emphasizes SIEM and log analysis, your Splunk lab project moves above your networking coursework, not the reverse.
The application itself: cover letters and ATS reality
Most mid-size and large companies run resumes through an applicant tracking system before a human ever sees them. That means matching language from the job posting matters more than clever phrasing. If the listing says "vulnerability management," use that exact phrase somewhere if it's true of your experience, rather than a synonym like "patch tracking."
A short cover letter (three to four sentences) still helps for smaller companies and referrals, even if larger firms barely read them. Use it to explain a career change directly instead of hoping the resume speaks for itself: "After five years in network administration, I moved toward security operations, building hands-on experience through home-lab detection engineering and completing Security+ and TryHackMe's SOC path. I'm looking to bring that background to a Tier 1 SOC analyst role." That's one sentence of context, not a résumé rewritten in paragraph form.
Referrals beat cold applications, every time
Applying cold through a careers page has a low response rate almost everywhere, security included. LinkedIn comments, local security meetups, and Discord communities tied to certifications or CTF platforms turn into actual referrals far more often than a perfect resume alone. Treat the resume as necessary but not sufficient — it opens the door once someone's already looking at it.
For more on building the hands-on experience that actually fills out that resume, check out Korra Studio's Breaking In and Certifications segments.
Written with AI assistance, reviewed and published by Michal Pilch (CISSP), Korra Studio.
This is one note from the Korra Studio knowledge base — the platform pairs every topic with 1-to-1 mentoring.
Get started freearrow_forward